Kavvo Connect 隐私政策
更新日期:2026年8月30日
生效日期:2026年8月30日
叩梦科技 Common Technology(叩梦科技新加坡、中国及法国等)(以下简称"叩梦科技"或"我们")深知个人信息对您的重要性,我们将按照法律法规的规定,保护您的个人信息及隐私安全。本隐私政策(以下简称"本政策")将帮助您了解以下内容:
我们如何收集和使用您的个人信息
我们如何存储和保护您的个人信息
我们如何共享、转让、公开披露您的个人信息
您如何管理您的个人信息
我们如何处理未成年人的个人信息
本政策如何更新
如何联系我们
请您在使用 Kavvo Connect 及相关服务前仔细阅读并理解本政策,以便做出适当的选择。
本政策适用于 Kavvo Connect(以下简称"本应用"或"我们"),由叩梦科技提供。Kavvo 是叩梦科技旗下的智能可穿戴设备品牌,Kavvo Connect 是配合 Kavvo 品牌智能手环、智能手表、智能耳机等设备使用的官方应用。
就本政策而言,叩梦科技新加坡(Common Technology Singapore)为全球最终数据控制者,对本应用在全球范围内收集和处理的个人信息承担最终数据控制者责任。对于中国地区的用户,深圳叩梦科技有限公司(Shenzhen Common Technology LTD.)为直接数据控制者;对于欧洲经济区(EEA)的用户,叩梦科技法国(Common Technology France)为直接数据控制者。
一、我们如何收集和使用您的个人信息
个人信息是指以电子或者其他方式记录的能够单独或者与其他信息结合识别特定自然人身份或者反映特定自然人活动情况的各种信息。我们收集您的个人信息主要是为了您能够使用本应用的核心功能,并保障设备与应用的正常运行。
我们仅会出于本政策所述的以下目的,收集和使用您的个人信息,并明确每项收集的合法性基础:
(一)为您提供账号服务
1. 账号登录
当您使用本应用时,您可以选择通过第三方平台账号(目前支持微信、Apple ID、Google 账号)登录。登录后,我们会获取您在第三方平台注册的公开信息(如账号唯一标识、头像、昵称),用于在本应用内创建您的账户。
合法性基础:合同必需。 若不提供上述信息,您将无法完成账号登录并使用本应用的核心功能。
2. 账号注销
您可以通过本应用"我的 > 设置 > 账号与安全 > 注销账号"路径注销您的账号。账号注销后,我们将停止为您提供产品或服务,并根据适用法律的要求删除或匿名化处理您的个人信息。注销账号后,您的账号信息将无法恢复,请谨慎操作。
(二)为您提供设备连接与管理服务
1. 设备绑定与连接
当您将 Kavvo 品牌智能手环、智能手表、智能耳机等设备通过本应用进行绑定和管理时,我们需要收集您的:
蓝牙信息:用于搜索、配对和连接设备。
设备信息:包括设备型号、设备序列号、固件版本、设备名称,用于识别设备并为设备提供适配服务。
合法性基础:合同必需。 若不提供上述信息,您将无法绑定和使用智能设备。
2. 设备数据同步
在您绑定设备后,我们会将设备收集的数据同步至本应用,以便您查看和管理。这些数据可能包括:
健康数据:心率、血氧饱和度、睡眠时长与质量、步数、运动距离、消耗卡路里、运动类型与时长、体重、身高、体脂率、身体年龄等。
运动数据:运动轨迹(GPS位置信息)、运动速度、运动配速等。
合法性基础:您的明确同意。 健康数据属于敏感个人信息,我们将在您首次使用相关功能时单独弹窗提示,征得您的明确同意后方开始收集。您可以在设备设置或应用设置中随时关闭数据同步或撤回同意,但撤回同意不会影响此前基于您同意已进行的处理活动的合法性。
3. 消息通知与来电提醒
当您开启消息通知、来电提醒等功能时,我们需要访问您的:
通知栏权限:用于将手机上的来电、短信、应用通知推送至您的设备。
通讯录权限:用于在设备上显示来电联系人姓名。
短信权限:用于在设备上显示短信内容。
通话记录权限:用于在设备上显示来电信息。
合法性基础:您的明确同意。 上述权限均为可选功能,您可以随时在手机系统设置中关闭相应权限。不开启上述权限,您仍可使用本应用的其他功能。
4. 蓝牙快门(相机控制)
当您使用设备作为蓝牙快门遥控手机拍照或录制视频时,我们需要访问您的:
相机权限:用于接收设备发出的拍照/录像指令。
合法性基础:您的明确同意。 此功能为可选功能,您可以在手机系统设置中关闭相机权限。
5. 固件升级(OTA)
当您更新设备固件时,我们需要使用以下权限:
应用安装权限:用于下载并安装设备固件更新包。
设备信息:用于判断设备当前固件版本并提供适配的更新包。
合法性基础:合同必需及正当利益。 固件升级旨在保障设备安全、修复已知问题及提升产品体验,是保障服务正常运行的必要措施。
6. 闹钟与日程提醒
当您设置设备闹钟或日程提醒时,我们需要访问您的存储权限,用于存储闹钟配置文件。
合法性基础:合同必需。
(三)为您提供数据分析与产品改进服务
1. 数据统计与分析
我们可能收集您的使用数据(包括应用功能使用频率、设备连接时长、崩溃日志等),用于分析用户群体特征、改善产品和服务质量。我们会对上述数据进行去标识化或匿名化处理,使其无法重新识别特定个人。
合法性基础:正当利益。 我们基于改进产品和服务的正当利益处理上述数据,并确保该处理不会对您的权利和自由造成不当影响。您可以通过本应用"我的 > 设置 > 隐私设置 > 使用数据收集"路径选择退出。
2. 用户体验改进计划
我们可能邀请您参与用户体验改进计划,此计划完全自愿。参与后,我们将收集您的使用习惯、偏好设置等数据,用于优化产品设计。
合法性基础:您的同意。
(四)依法收集与使用
在以下情形中,我们收集和使用您的个人信息无需征得您的同意:
与国家安全、国防安全直接相关的;
与公共安全、公共卫生、重大公共利益直接相关的;
与犯罪侦查、起诉、审判和判决执行等直接相关的;
出于维护您或其他个人的生命、财产等重大合法权益但又很难得到本人同意的;
所收集的个人信息是您自行向社会公众公开的;
从合法公开披露的信息中收集的您的个人信息,如合法的新闻报道、政府信息公开等渠道;
根据您的要求签订和履行合同所必需的;
用于维护所提供的产品或服务的安全稳定运行所必需的,例如发现、处置产品或服务的故障;
法律法规规定的其他情形。
(五)设备权限调用汇总
为保障本应用相关功能的实现,我们可能申请或使用操作系统的相关权限。以下为权限调用清单:
| 权限名称 | 使用场景/目的 | 是否可关闭 |
|---|
| 蓝牙 | 搜索、连接和管理智能设备 | 是(但将无法使用设备连接功能) |
| 位置信息 | 记录运动轨迹(仅当您开启运动模式时) | 是 |
| 相机 | 蓝牙快门遥控拍照/录像 | 是 |
| 通讯录 | 在设备上显示来电联系人姓名 | 是 |
| 短信 | 在设备上显示短信内容 | 是 |
| 通话记录 | 在设备上显示来电信息 | 是 |
| 存储 | 存储闹钟配置、缓存数据 | 是 |
| 身体传感器 | 获取心率等健康数据 | 是(但将无法同步健康数据) |
| 通知栏 | 推送消息至设备 | 是 |
| 附近设备 | 发现并连接附近的智能设备 | 是(但将影响设备发现功能) |
| 安装应用 | OTA固件升级 | 是(但将无法更新设备固件) |
| 网络/Wi-Fi | 数据传输、账号登录 | 是(但将无法使用联网功能) |
您可以在手机系统设置中对上述权限进行管理。关闭权限后,对应的功能将无法使用,但不会影响其他功能的使用。
二、我们如何存储和保护您的个人信息
(一)存储地点
我们在全球多个国家或地区设有数据中心,以提供稳定、快速的服务。根据您所在国家或地区的法律法规要求,我们遵循数据本地化存储原则:
中国用户的个人信息存储于中国境内的数据中心;
美国及拉丁美洲地区用户的个人信息存储于美国的数据中心;
欧洲经济区(EEA)、中东及非洲地区用户的个人信息存储于德国的数据中心;
亚太地区(包括日本、韩国、东南亚等)用户的个人信息存储于新加坡的数据中心;
俄罗斯用户的个人信息存储于俄罗斯的数据中心;
印度用户的个人信息存储于印度的数据中心。
(二)存储期限
我们仅在本政策所述目的所必需的期间和法律法规要求的时限内保留您的个人信息。在超出存储期限后,我们将对个人信息进行删除或匿名化处理。但在以下情况下,我们可能延长存储期限:
遵守适用的法律法规等有关规定;
遵守法院判决、裁定或其他法律程序的规定;
遵守相关政府机关或法定授权组织的要求;
为执行相关服务协议或本政策、维护社会公共利益,为保护我们的客户、我们或我们的关联公司、其他用户或雇员的人身财产安全或其他合法权益所合理必需的用途。
(三)安全保护措施
我们已使用符合业界标准的安全防护措施保护您提供的个人信息,防止数据遭到未经授权访问、公开披露、使用、修改、损坏或丢失。我们会采取一切合理可行的措施,保护您的个人信息。
我们会采取一切合理可行的措施,确保未收集无关的个人信息。我们只会在达成本政策所述目的所需的期限内保留您的个人信息,除非需要延长保留期或受到法律的允许。
互联网环境并非百分之百安全,我们将尽力确保您发送给我们的任何信息的安全性。如果我们的物理、技术或管理防护设施遭到破坏,导致信息被非授权访问、公开披露、篡改或毁坏,导致您的合法权益受损,我们将承担相应的法律责任。
在不幸发生个人信息安全事件后,我们将按照法律法规的要求,及时向您告知:安全事件的基本情况和可能的影响、我们已采取或将要采取的处置措施、您可自主防范和降低风险的建议、对您的补救措施等。我们将及时将事件相关情况以邮件、信函、电话、推送通知等方式告知您。难以逐一告知个人信息主体时,我们会采取合理、有效的方式发布公告。同时,我们还将按照监管部门要求,主动上报个人信息安全事件的处置情况。
三、我们如何共享、转让、公开披露您的个人信息
(一)共享
我们不会与叩梦科技以外的任何公司、组织和个人分享您的个人信息,但以下情况除外:
在获取明确同意的情况下共享:获得您的明确同意后,我们会与其他方共享您的个人信息。
与授权合作伙伴共享:我们可能委托授权合作伙伴为您提供某些服务或代表我们履行职能。我们仅会出于本政策声明的合法、正当、必要、特定、明确的目的共享您的信息,授权合作伙伴只能接触到其履行职责所需信息,且不得将此信息用于其他任何目的。目前,我们的授权合作伙伴包括以下类型:
第三方登录服务提供商:微信(腾讯)、Apple、Google。当您使用上述第三方账号登录时,我们会与该第三方进行必要的信息交互。
数据分析服务提供商:我们可能使用第三方分析工具(如 Google Analytics、Firebase 等)来帮助我们了解用户的使用习惯,以改进产品。这些工具收集的数据为去标识化或匿名化数据。
云服务提供商:我们使用全球分布的云服务来存储数据,服务提供商的选择根据您所在区域而定(如中国的阿里云/腾讯云、美国的 AWS、欧洲的 Azure 等)。
与关联公司共享:您的个人信息可能会与叩梦科技 Common Technology(叩梦科技新加坡、中国及法国等)旗下的关联公司共享。我们只会共享必要的个人信息,且受本政策中所声明目的的约束。关联公司如要改变个人信息的处理目的,将再次征求您的授权同意。
在法定情形下共享:我们可能会根据法律法规规定、诉讼争议解决需要,或按行政、司法机关依法提出的要求,对外共享您的个人信息。
(二)转让
我们不会将您的个人信息转让给任何公司、组织和个人,但以下情况除外:
在获取明确同意的情况下转让:获得您的明确同意后,我们会向其他方转让您的个人信息;
在涉及合并、收购或破产清算时,如涉及到个人信息转让,我们会在要求新的持有您个人信息的公司、组织继续受本政策的约束,否则我们将要求该公司、组织重新向您征求授权同意。
(三)公开披露
我们仅会在以下情况下,公开披露您的个人信息:
获得您明确同意后;
基于法律的披露:在法律、法律程序、诉讼或政府主管部门强制性要求的情况下,我们可能会公开披露您的个人信息。
四、您如何管理您的个人信息
按照适用的法律法规,我们保障您对自己的个人信息行使以下权利:
(一)访问、更正您的个人信息
您可以通过本应用"我的"页面访问您的个人信息(如头像、昵称、健康数据、运动数据等)。如需更正或补充,您可以在相应页面直接修改。
(二)删除您的个人信息
在以下情形中,您可以向我们提出删除个人信息的请求:
如果我们处理个人信息的行为违反法律法规;
如果我们收集、使用您的个人信息,却未征得您的同意;
如果我们处理个人信息的行为违反了与您的约定;
如果您不再使用我们的产品或服务,或您注销了账号;
如果我们不再为您提供产品或服务。
您可以通过本应用内反馈、发送邮件至 privacy@kavvo.com 等方式提出删除请求。
(三)撤回您的同意
您可以通过以下方式撤回您的同意:
在手机系统设置中关闭您已授权的权限;
在本应用"我的 > 设置 > 隐私设置"中管理您的隐私偏好;
对于健康数据的收集,您可以在设备设置中关闭数据同步。
撤回同意后,我们将不再处理相应的个人信息。但您撤回同意的决定,不会影响此前基于您的授权而开展的个人信息处理。
(四)注销您的账号
您可以通过本应用"我的 > 设置 > 账号与安全 > 注销账号"路径注销您的账号。账号注销后,我们将停止为您提供产品或服务,并根据适用法律的要求删除或匿名化处理您的个人信息。
(五)获取您的个人信息副本
您有权获取您的个人信息副本。您可以通过本应用"我的 > 设置 > 隐私设置 > 导出数据"路径申请导出您的数据。如该功能尚未上线,您可通过联系我们的隐私保护部门提出申请。
(六)响应您的上述请求
为保障安全,我们可能需要您提供书面请求,或以其他方式证明您的身份。我们将在收到您的请求并验证身份后的 30 天内答复。
对于您合理的请求,我们原则上不收取费用。但对于多次重复、超出合理限度的请求,我们将视情况收取一定成本费用。对于无端重复、需要过多技术手段、给他人合法权益带来风险或者非常不切实际的请求,我们可能会予以拒绝。
五、我们如何处理未成年人的个人信息
我们的产品和服务主要面向成年人。我们不会主动收集未成年人的个人信息。
根据不同国家或地区的法律法规,我们对未成年人的界定及保护措施如下:
中国:未满 14 周岁的用户视为儿童。儿童的监护人需要仔细阅读本政策及《儿童个人信息保护规则》,并在征得监护人明确同意的前提下,由监护人帮助儿童使用我们的产品或服务。
美国:未满 13 周岁的用户视为儿童(依据 COPPA)。我们不会在未获得可证实的父母同意的情况下,故意收集 13 周岁以下儿童的个人信息。
欧洲经济区(EEA):儿童年龄界定依据各成员国法律(通常为 13 至 16 周岁)。我们依据 GDPR 及成员国相关法律,仅在获得监护人授权或同意的情况下处理儿童个人信息。
其他地区:依据当地法律对未成年人的年龄界定执行相应的保护措施。
如果您是儿童的监护人,当您对您所监护的儿童的个人信息有相关疑问时,请通过本政策列明的联系方式与我们联系。
如果我们发现我们在未事先获得可证实的监护人同意的情况下收集了儿童的个人信息,我们将设法尽快删除相关数据。
六、本政策如何更新
我们可能会适时对本政策进行修订。当本政策的条款发生变更时,我们会在版本更新时以适当的方式向您提示变更后的政策,并再次征得您的同意。
未经您明确同意,我们不会削减您按照本政策所应享有的权利。
对于重大变更,我们还会提供更为显著的通知(包括但不限于应用内弹窗、推送通知、邮件等方式)。
本政策所指的重大变更包括但不限于:
我们的服务模式发生重大变化,如处理个人信息的目的、处理的个人信息类型、个人信息的使用方式等;
我们在所有权结构、组织架构等方面发生重大变化,如业务调整、破产并购等引起的所有者变更等;
个人信息共享、转让或公开披露的主要对象发生变化;
您参与个人信息处理方面的权利及其行使方式发生重大变化;
我们负责处理个人信息安全的责任部门、联络方式及投诉渠道发生变化时;
个人信息安全影响评估报告表明存在高风险时。
七、如何联系我们
全球最终数据控制者: 叩梦科技新加坡(Common Technology Singapore)
中国地区直接数据控制者: 深圳叩梦科技有限公司(Shenzhen Common Technology LTD.)
欧洲经济区(EEA)直接数据控制者: 叩梦科技法国(Common Technology France)
如果您对本政策有任何疑问、意见或建议,或者您需要行使您的个人信息权利,请通过以下方式与我们联系:
电子邮箱:privacy@kavvo.com
我们将在收到您的反馈后 30 天内予以回复。
如果您对我们的回复不满意,特别是您认为我们的个人信息处理行为损害了您的合法权益,您还可以向您所在国家或地区的数据保护监管机构进行投诉或举报,或者向有管辖权的法院提起诉讼。
附录:儿童个人信息保护规则
叩梦科技 Common Technology(叩梦科技新加坡、中国及法国等)(以下简称"我们")深知儿童个人信息和隐私安全的重要性。本规则旨在向监护人(以下简称"您")和您所监护的儿童(指未满14周岁的未成年人,以下简称"儿童")说明我们如何收集、使用、存储和处理儿童的个人信息。
本规则主要适用于中国地区未满14周岁的儿童用户。对于其他地区,请参照本政策第五条中的差异化规定。
如果您是儿童,请务必通知您的监护人一起阅读本规则,并在征得您的监护人同意后,由监护人帮助您使用我们的产品或服务。
一、我们如何收集和使用儿童个人信息
当儿童使用 Kavvo Connect 及相关服务时,我们仅会在获得监护人明确同意的情况下,收集实现服务功能所必需的最少儿童个人信息。
我们收集的儿童个人信息类型仅限于:
账号信息:当儿童通过第三方账号(微信、Apple ID、Google 账号)登录时,我们获取该第三方账号的公开信息(如账号唯一标识、头像、昵称)。
设备数据:当儿童使用 Kavvo 智能设备时,设备收集的健康数据(心率、血氧、睡眠、步数等)和运动数据。
我们如何使用这些信息:
为儿童提供设备连接、数据同步和展示服务;
帮助监护人了解儿童的活动和健康状况。
二、征得监护人的同意
我们收集和使用儿童个人信息前,将通过以下方式征得监护人的明确同意:
在儿童首次使用本应用时,弹窗提示监护人阅读并同意本规则;
监护人可以通过勾选"同意"等方式明确表示同意。
三、儿童个人信息的存储和保护
我们严格遵守法律法规,对儿童个人信息采取更严格的保护措施:
儿童个人信息按照本政策第二条所述的"数据本地化存储"原则进行存储;
我们采取加密、访问控制等技术措施保护儿童个人信息的安全;
我们设定了儿童个人信息访问权限,仅授权必要人员可以访问。
四、儿童个人信息的共享
我们不会与第三方共享儿童个人信息,除非:
获得监护人的明确同意;
法律法规要求或政府主管部门的强制性要求。
五、监护人的权利
您作为监护人,享有以下权利:
查阅:您可以申请查阅我们收集的儿童个人信息;
更正:如发现儿童个人信息有误,您可以申请更正;
删除:您可以要求我们删除所收集的儿童个人信息;
撤回同意:您可以随时撤回您对我们收集和使用儿童个人信息的同意。
您可以通过本政策第七条列明的联系方式行使上述权利。
六、本规则的更新
我们可能会适时更新本规则。更新后的规则会在应用内显著位置进行提示,并重新征得您的同意。
Kavvo Connect Privacy Policy
Last Updated: August 30, 2026
Effective Date: August 30, 2026
Common Technology (comprising Common Technology Singapore, Shenzhen Common Technology LTD., Common Technology France, and other affiliates) (hereinafter referred to as "Common Technology," "we," "us," or "our") understands the importance of personal data to you. We will protect your personal data and privacy in accordance with applicable laws and regulations. This Privacy Policy (hereinafter referred to as "this Policy") will help you understand the following:
How We Collect and Use Your Personal Data
How We Store and Protect Your Personal Data
How We Share, Transfer, and Publicly Disclose Your Personal Data
How You Manage Your Personal Data
How We Handle Minors' Personal Data
How This Policy Is Updated
How to Contact Us
Please read and understand this Policy carefully before using Kavvo Connect and related services so that you can make informed choices.
This Policy applies to Kavvo Connect (hereinafter referred to as the "App" or "we"), which is provided by Common Technology. Kavvo is a smart wearable device brand under Common Technology, and Kavvo Connect is the official application designed to work with Kavvo-branded smart bands, smart watches, smart earphones, and other devices.
For the purposes of this Policy, Common Technology Singapore serves as the ultimate global data controller, bearing final data controller responsibility for personal data collected and processed through the App worldwide. For users in the People's Republic of China (excluding Hong Kong, Macau, and Taiwan for the purposes of this Policy), Shenzhen Common Technology LTD. serves as the direct data controller. For users in the European Economic Area (EEA), Common Technology France serves as the direct data controller.
1. How We Collect and Use Your Personal Data
Personal data refers to any information recorded electronically or otherwise that can, alone or in combination with other information, identify a specific natural person or reflect the activities of a specific natural person. We collect your personal data primarily to enable you to use the core functions of the App and to ensure the proper operation of the device and application.
We will only collect and use your personal data for the purposes described in this Policy, and we specify the legal basis for each collection activity:
(1) Providing Account Services
1. Account Login
When you use the App, you may choose to log in via a third-party platform account (currently supporting WeChat, Apple ID, and Google Account). After login, we will obtain the public information associated with your third-party account (such as unique account identifier, profile picture, and nickname) to create your account within the App.
Legal Basis: Contractual Necessity. If you do not provide the above information, you will not be able to complete account login and use the core functions of the App.
2. Account Deletion
You may delete your account via the path "Profile > Settings > Account & Security > Delete Account" within the App. After your account is deleted, we will cease to provide you with products or services and will delete or anonymize your personal data in accordance with the requirements of applicable law. Once your account is deleted, your account information cannot be recovered. Please proceed with caution.
(2) Providing Device Connection and Management Services
1. Device Binding and Connection
When you bind and manage Kavvo-branded smart bands, smart watches, smart earphones, and other devices through the App, we need to collect:
Bluetooth Information: Used to search for, pair with, and connect to your device.
Device Information: Including device model, device serial number, firmware version, and device name, used to identify the device and provide compatible services.
Legal Basis: Contractual Necessity. If you do not provide the above information, you will not be able to bind and use your smart device.
2. Device Data Synchronization
Once you have bound your device, we will synchronize data collected by the device to the App for you to view and manage. This data may include:
Health Data: Heart rate, blood oxygen saturation, sleep duration and quality, steps, exercise distance, calories burned, exercise type and duration, weight, height, body fat percentage, body age, and similar metrics.
Exercise Data: Exercise route (GPS location data), exercise speed, exercise pace, etc.
Legal Basis: Your Explicit Consent. Health data constitutes special category data (sensitive personal data). We will separately prompt you via a pop-up notice when you first use the relevant function, and will only begin collection after obtaining your explicit consent. You may disable data synchronization or withdraw your consent at any time in the device settings or app settings; however, withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
3. Message Notifications and Incoming Call Alerts
When you enable message notifications, incoming call alerts, and similar functions, we need to access:
Notification Permission: Used to push incoming calls, SMS messages, and app notifications from your phone to your device.
Contacts Permission: Used to display the name of incoming callers on your device.
SMS Permission: Used to display SMS message content on your device.
Call Log Permission: Used to display incoming call information on your device.
Legal Basis: Your Explicit Consent. The above permissions are all optional features. You may disable the corresponding permissions at any time in your phone's system settings. Not enabling these permissions will not affect your ability to use other functions of the App.
4. Bluetooth Shutter (Camera Control)
When you use your device as a Bluetooth shutter to remotely control your phone's camera for taking photos or recording videos, we need to access:
Camera Permission: Used to receive photo/video capture commands from your device.
Legal Basis: Your Explicit Consent. This is an optional feature. You may disable the camera permission in your phone's system settings.
5. Firmware Upgrade (OTA)
When you update your device firmware, we need to use the following permissions:
App Installation Permission: Used to download and install device firmware update packages.
Device Information: Used to determine the current firmware version of your device and provide compatible update packages.
Legal Basis: Contractual Necessity and Legitimate Interests. Firmware upgrades are designed to ensure device security, fix known issues, and improve product experience, and are necessary measures to maintain the proper operation of the service.
6. Alarm and Schedule Reminders
When you set device alarms or schedule reminders, we need to access your storage permission to store alarm configuration files.
Legal Basis: Contractual Necessity.
(3) Providing Data Analytics and Product Improvement Services
1. Data Statistics and Analytics
We may collect your usage data (including frequency of app feature usage, device connection duration, crash logs, etc.) to analyze user population characteristics and improve product and service quality. We will de-identify or anonymize the above data so that it cannot be used to re-identify a specific individual.
Legal Basis: Legitimate Interests. We process the above data based on our legitimate interests in improving our products and services, and we ensure that such processing does not unduly affect your rights and freedoms. You may opt out via the path "Profile > Settings > Privacy Settings > Usage Data Collection" within the App.
2. User Experience Improvement Program
We may invite you to participate in our User Experience Improvement Program, which is entirely voluntary. If you participate, we will collect data such as your usage habits and preference settings to optimize product design.
Legal Basis: Your Consent.
(4) Collection and Use in Accordance with Law
Under the following circumstances, we may collect and use your personal data without your consent:
Where it is directly related to national security or national defense;
Where it is directly related to public safety, public health, or major public interests;
Where it is directly related to criminal investigation, prosecution, trial, or enforcement of judgments;
Where it is necessary to protect the life, property, or other significant legitimate rights and interests of you or other individuals, and obtaining consent is difficult;
Where the personal data is disclosed by you to the public at your own discretion;
Where the personal data is collected from lawfully and publicly disclosed information, such as lawful news reports, government information disclosure, and other channels;
Where it is necessary for the conclusion and performance of a contract at your request;
Where it is necessary to maintain the safe and stable operation of the products or services provided, such as detecting and resolving product or service malfunctions;
Other circumstances as provided by applicable laws and regulations.
(5) Summary of Device Permission Requests
To enable the relevant functions of the App, we may request or use certain operating system permissions. The following is a summary of permission requests:
| Permission | Purpose / Scenario | Can Be Disabled |
|---|
| Bluetooth | Search for, connect to, and manage smart devices | Yes (but device connection will be unavailable) |
| Location | Record exercise routes (only when exercise mode is active) | Yes |
| Camera | Bluetooth shutter remote photo/video capture | Yes |
| Contacts | Display incoming caller names on device | Yes |
| SMS | Display SMS content on device | Yes |
| Call Log | Display incoming call information on device | Yes |
| Storage | Store alarm configurations and cache data | Yes |
| Body Sensors | Obtain heart rate and other health data | Yes (but health data sync will be unavailable) |
| Notifications | Push notifications to device | Yes |
| Nearby Devices | Discover and connect to nearby smart devices | Yes (but device discovery will be affected) |
| App Installation | OTA firmware upgrade | Yes (but firmware updates will be unavailable) |
| Network / Wi-Fi | Data transmission and account login | Yes (but network-dependent features will be unavailable) |
You can manage these permissions in your phone's system settings. Disabling permissions will prevent the corresponding functions from being available but will not affect the use of other functions.
2. How We Store and Protect Your Personal Data
(1) Storage Location
We maintain data centers in multiple countries and regions around the world to provide stable and responsive services. In accordance with the laws and regulations of your country or region, we adhere to the principle of data localization:
Personal data of users in China is stored in data centers within the People's Republic of China;
Personal data of users in the United States and Latin America is stored in data centers in the United States;
Personal data of users in the European Economic Area (EEA), the Middle East, and Africa is stored in data centers in Germany;
Personal data of users in the Asia-Pacific region (including Japan, South Korea, Southeast Asia, etc.) is stored in data centers in Singapore;
Personal data of users in Russia is stored in data centers in Russia;
Personal data of users in India is stored in data centers in India.
(2) Retention Period
We will retain your personal data only for the period necessary to fulfill the purposes described in this Policy and as required by applicable laws and regulations. After the retention period expires, we will delete or anonymize your personal data. However, we may extend the retention period under the following circumstances:
To comply with applicable laws and regulations;
To comply with court judgments, rulings, or other legal procedure requirements;
To comply with requirements of relevant government authorities or legally authorized bodies;
Where reasonably necessary to enforce relevant service agreements or this Policy, safeguard public interests, or protect the personal and property safety or other legitimate rights and interests of our customers, us, our affiliates, other users, or employees.
(3) Security Measures
We have implemented industry-standard security measures to protect the personal data you provide against unauthorized access, public disclosure, use, modification, damage, or loss. We will take all reasonably practicable measures to protect your personal data.
We will take all reasonably practicable measures to ensure that irrelevant personal data is not collected. We will retain your personal data only for the period necessary to fulfill the purposes described in this Policy, unless extended retention is required or permitted by law.
The internet environment is not 100% secure. We will use our best efforts to ensure the security of any information you send to us. If our physical, technical, or administrative safeguards are breached, resulting in unauthorized access, public disclosure, alteration, or destruction of information, and causing damage to your legitimate rights and interests, we will bear corresponding legal liability.
In the unfortunate event of a personal data security incident, we will promptly inform you, in accordance with legal and regulatory requirements, of: the basic facts and potential impact of the incident; the measures we have taken or will take to address it; recommendations for you to independently prevent and mitigate risks; and remedial measures available to you. We will promptly inform you of the relevant circumstances via email, mail, telephone, push notification, or other means. Where it is difficult to notify each data subject individually, we will issue a public announcement in a reasonable and effective manner. At the same time, we will proactively report the handling of personal data security incidents to regulatory authorities as required.
3. How We Share, Transfer, and Publicly Disclose Your Personal Data
(1) Sharing
We will not share your personal data with any company, organization, or individual outside of Common Technology, except in the following circumstances:
Sharing with Your Explicit Consent: We will share your personal data with other parties after obtaining your explicit consent.
Sharing with Authorized Partners: We may engage authorized partners to provide certain services on your behalf or to perform functions on our behalf. We will only share your data for the lawful, legitimate, necessary, specific, and explicit purposes stated in this Policy. Authorized partners will only have access to the information necessary to perform their duties and may not use such information for any other purpose. Currently, our authorized partners include the following categories:
Third-Party Login Service Providers: WeChat (Tencent), Apple, and Google. When you log in using any of these third-party accounts, we will engage in necessary information exchange with the relevant third party.
Data Analytics Service Providers: We may use third-party analytics tools (such as Google Analytics, Firebase, etc.) to help us understand user usage patterns and improve our products. The data collected by these tools is de-identified or anonymized.
Cloud Service Providers: We use globally distributed cloud services to store data. The selection of service providers depends on your region (e.g., Alibaba Cloud / Tencent Cloud in China, AWS in the United States, Azure in Europe, etc.).
Sharing with Affiliates: Your personal data may be shared with affiliated companies under Common Technology (comprising Common Technology Singapore, Shenzhen Common Technology LTD., Common Technology France, and other affiliates). We will only share the necessary personal data, and such sharing will be subject to the purposes stated in this Policy. If an affiliate wishes to change the purpose of processing personal data, it will seek your authorized consent again.
Sharing under Legal Circumstances: We may share your personal data externally as required by applicable laws and regulations, for the purpose of resolving litigation disputes, or as required by administrative or judicial authorities in accordance with the law.
(2) Transfer
We will not transfer your personal data to any company, organization, or individual, except in the following circumstances:
Transfer with your explicit consent: After obtaining your explicit consent, we will transfer your personal data to another party;
In the event of a merger, acquisition, or bankruptcy liquidation involving a transfer of personal data, we will require the new company or organization holding your personal data to continue to be bound by this Policy; otherwise, we will require such company or organization to seek your authorized consent anew.
(3) Public Disclosure
We will publicly disclose your personal data only under the following circumstances:
After obtaining your explicit consent;
Legal Disclosure: We may publicly disclose your personal data where required by law, legal proceedings, litigation, or mandatory requirements of government authorities.
4. How You Manage Your Personal Data
In accordance with applicable laws and regulations, we guarantee the following rights for you with respect to your personal data:
(1) Access and Correction of Your Personal Data
You may access your personal data (such as profile picture, nickname, health data, exercise data, etc.) through the "Profile" page of the App. If you need to correct or supplement your data, you may do so directly on the corresponding page.
(2) Deletion of Your Personal Data
You may request that we delete your personal data under the following circumstances:
Where our processing of personal data violates applicable laws and regulations;
Where we collected or used your personal data without obtaining your consent;
Where our processing of personal data violates our agreement with you;
Where you no longer use our products or services, or you have deleted your account;
Where we no longer provide products or services to you.
You may submit a deletion request through in-app feedback or by sending an email to privacy@kavvo.com.
(3) Withdrawal of Your Consent
You may withdraw your consent in the following ways:
Disabling the permissions you previously granted in your phone's system settings;
Managing your privacy preferences via "Profile > Settings > Privacy Settings" within the App;
For health data collection, disabling data synchronization in your device settings.
After you withdraw your consent, we will cease processing the corresponding personal data. However, your decision to withdraw consent will not affect the lawfulness of processing carried out based on your prior authorization.
(4) Deletion of Your Account
You may delete your account via the path "Profile > Settings > Account & Security > Delete Account" within the App. After your account is deleted, we will cease to provide you with products or services and will delete or anonymize your personal data in accordance with the requirements of applicable law.
(5) Obtaining a Copy of Your Personal Data
You have the right to obtain a copy of your personal data. You may request to export your data via the path "Profile > Settings > Privacy Settings > Export Data" within the App. If this function is not yet available, you may submit a request by contacting our privacy department.
(6) Responding to Your Requests
For security purposes, we may require you to submit a written request or otherwise verify your identity. We will respond within 30 days of receiving your request and verifying your identity.
In principle, we do not charge a fee for reasonable requests. However, for repeated or excessive requests, we may charge a cost-based fee as appropriate. We may decline requests that are manifestly unfounded, excessive, require disproportionate technical measures, pose a risk to the legitimate rights and interests of others, or are highly impractical.
5. How We Handle Minors' Personal Data
Our products and services are primarily intended for adults. We do not knowingly collect personal data from minors.
In accordance with the laws and regulations of different countries and regions, our definition of minors and corresponding protective measures are as follows:
China: Users under the age of 14 are considered children. Guardians of children should carefully read this Policy and the Children's Privacy Notice, and help children use our products or services only after obtaining the guardian's explicit consent.
United States: Users under the age of 13 are considered children (pursuant to COPPA). We do not knowingly collect personal data from children under 13 without obtaining verifiable parental consent.
European Economic Area (EEA) : The age threshold for children is determined by the laws of each Member State (typically between 13 and 16 years of age). We process children's personal data in accordance with the GDPR and relevant Member State laws, and only with parental authorization or consent.
Other Regions: Corresponding protective measures are implemented in accordance with the age thresholds defined by local laws.
If you are a guardian of a child and have questions regarding the personal data of the child under your guardianship, please contact us using the contact information provided in this Policy.
If we discover that we have collected personal data from a child without verifiable parental consent, we will take steps to delete such data as soon as possible.
6. How This Policy Is Updated
We may revise this Policy from time to time. When the terms of this Policy change, we will notify you of the updated Policy in an appropriate manner at the time of the version update, and will seek your consent again.
We will not reduce the rights you are entitled to under this Policy without your explicit consent.
For material changes, we will provide more prominent notice (including but not limited to in-app pop-ups, push notifications, email, and other means).
Material changes referred to in this Policy include but are not limited to:
Material changes in our service model, such as changes in the purposes of processing personal data, the types of personal data processed, the methods of using personal data, etc.;
Material changes in our ownership structure, organizational structure, etc., such as changes in ownership due to business adjustments, bankruptcy, mergers, or acquisitions;
Changes in the primary recipients of shared, transferred, or publicly disclosed personal data;
Material changes in your rights with respect to personal data processing and how such rights are exercised;
Changes in the department responsible for personal data security, contact information, and complaint channels;
Where a personal data security impact assessment report indicates a high risk.
7. How to Contact Us
Ultimate Global Data Controller: Common Technology Singapore
Direct Data Controller for China: Shenzhen Common Technology LTD.
Direct Data Controller for the European Economic Area (EEA): Common Technology France
If you have any questions, comments, or suggestions regarding this Policy, or if you wish to exercise your personal data rights, please contact us via:
Email: privacy@kavvo.com
We will respond to your inquiry within 30 days of receipt.
If you are dissatisfied with our response, particularly if you believe that our processing of personal data has infringed upon your legitimate rights and interests, you may also file a complaint or report with the data protection supervisory authority in your country or region, or bring a lawsuit before a court of competent jurisdiction.
Supplemental Children's Privacy Notice
Common Technology (comprising Common Technology Singapore, Shenzhen Common Technology LTD., Common Technology France, and other affiliates) (hereinafter referred to as "we," "us," or "our") understands the importance of children's personal data and privacy. This Supplemental Children's Privacy Notice is intended to explain to guardians (hereinafter referred to as "you") and the children under your guardianship (referring to minors under the age of 14, hereinafter referred to as "children") how we collect, use, store, and process children's personal data.
This Notice primarily applies to children under the age of 14 in China. For other regions, please refer to the differentiated provisions in Section 5 of this Policy.
If you are a child, please ensure that your guardian reads this Notice together with you, and have your guardian help you use our products or services only after obtaining your guardian's consent.
1. How We Collect and Use Children's Personal Data
When a child uses Kavvo Connect and related services, we will only collect the minimum personal data necessary to fulfill the service functions, and only after obtaining the guardian's explicit consent.
The types of children's personal data we collect are limited to:
Account Information: When a child logs in via a third-party account (WeChat, Apple ID, or Google Account), we obtain the public information associated with that third-party account (such as unique account identifier, profile picture, and nickname).
Device Data: When a child uses a Kavvo smart device, the device collects health data (heart rate, blood oxygen, sleep, steps, etc.) and exercise data.
How we use this information:
To provide the child with device connection, data synchronization, and display services;
To help the guardian understand the child's activity and health status.
2. Obtaining Guardian Consent
Before collecting and using children's personal data, we will obtain the guardian's explicit consent through the following means:
When a child first uses the App, a pop-up notice will prompt the guardian to read and agree to this Notice;
The guardian may explicitly indicate consent by checking "Agree" or similar means.
3. Storage and Protection of Children's Personal Data
We strictly comply with applicable laws and regulations and implement stricter protective measures for children's personal data:
Children's personal data is stored in accordance with the data localization principles described in Section 2 of this Policy;
We employ encryption, access control, and other technical measures to protect the security of children's personal data;
We have established access restrictions for children's personal data, granting access only to authorized personnel.
4. Sharing of Children's Personal Data
We will not share children's personal data with third parties except:
With the guardian's explicit consent;
Where required by applicable laws and regulations or mandatory requirements of government authorities.
5. Guardian's Rights
As a guardian, you have the following rights:
Access: You may request to access the children's personal data we have collected;
Correction: If you discover that any children's personal data is inaccurate, you may request a correction;
Deletion: You may request that we delete the children's personal data we have collected;
Withdrawal of Consent: You may withdraw your consent to our collection and use of children's personal data at any time.
You may exercise the above rights by contacting us using the contact information provided in Section 7 of this Policy.
6. Updates to This Notice
We may update this Notice from time to time. The updated Notice will be prominently displayed within the App, and we will seek your consent again.